CVE Tools

Secure-elements

14 CVEs tracked since 2006. Since May 2006, none of them reached CISA KEV.

Secure-elements CVEs per month

May 2006 to May 2006. Point at a month, or focus the strip and use the arrow keys.
Secure-elements CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2006-05140

Products

The products that kept showing up in Secure-elements's monthly top three, with their CVEs summed over those months.

  1. C5 Enterprise Vulnerability Management71 month
  2. Class 5 Enterprise Vulnerability Management71 month

Latest CVEs

The 14 most recently published vulnerabilities affecting Secure-elements.

  1. CVE-2006-2705Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of service via a large number of forged client registration messages.5.0
  2. CVE-2006-2715The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 does not enforce access control, which allows remote attackers to gain access to servers via the console.7.5
  3. CVE-2006-2707Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to c...5.0
  4. CVE-2006-2712Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest, which allows remote attackers to modify and replay messages.5.0
  5. CVE-2006-2709Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remote attackers to (1) execute arbitrary code on a client or (2) forge messages ...5.0
  6. CVE-2006-2706Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause a denial of service via forged "session start" messages that cause AVR to connect to arbitrary hosts.5.0
  7. CVE-2006-2704Secure Elements Class 5 AVR server and client (aka C5 EVM) before 2.8.1 send messages in cleartext, which allows remote attackers to read sensitive vulnerability information.5.0
  8. CVE-2006-2714Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not validate the CEID of an incoming message, which allows remote attackers to send messages to a protected asset without knowing t...5.0
  9. CVE-2006-2710Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allows remote attackers with the key to decrypt communications.5.0
  10. CVE-2006-2713Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates predictable CEIDs, which allows remote attackers to determine the CEID of a protected asset, which can be used in other attack...5.0
  11. CVE-2006-2716Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a hard-coded user ID and password, which allows remote attackers to gain access to the server.7.5
  12. CVE-2006-2708Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size for (1) EM_GET_CE_PARAMETER and (2) EM_SET_CE_PARAMETER m...5.0
  13. CVE-2006-2711Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to...5.0
  14. CVE-2006-2717Unspecified vulnerability in Secure Elements Class 5 AVR client and server (aka C5 EVM) before 2.8.1 allows authenticated attackers to overwrite arbitrary files (1) on a server during an update or ...4.0

The record

Peak rank
#3 in May 2006
Busiest month shown
May 2006, 14 CVEs
Months with a KEV entry
0 since May 2006
Monthly snapshots
1 since 2006
Secure-elements's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store